Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Attacks/Breaches

11/15/2016
09:00 AM
Jai Vijayan
Jai Vijayan
Slideshows
Connect Directly
Twitter
LinkedIn
RSS
E-Mail
50%
50%

The 7 Most Significant Government Data Breaches

Mega compromises at federal and state agencies over the past three years has compromised everything from personal data on millions to national security secrets.
Previous
1 of 8
Next

Data maintained by Privacy Rights Clearinghouse shows that federal and state government agencies publicly disclosed a total of 203 data breaches over the past five years.

In all, the breaches resulted in nearly 47 million records being stolen, exposed or otherwise compromised. The number of breached records does not include the numerous cases where agencies either did not disclose the scope of their data breach or the actual number of records that might have been involved.

It also does not include data from incidents like Edward Snowden’s theft of classified documents from the National Security Agency (NSA) or the recently disclosed theft of 50 TB of government data by another former contractor for the NSA and other federal agencies.

In terms of raw numbers, federal and state government agencies suffereda lot fewer breaches and exposed fewer data records than private companies. PRC numbers show that between 2012 and 2016 for instance, financial and insurance companies, retailers, and other businesses disclosed some 950 breaches involving 244.5 million records.

What makes the government breaches more significant though is the kind of information involved. In a majority of cases, government breaches involved personally identifying data, such as names, Social Security numbers, and birthdates, the loss of which have substantially greater consequences for victims than breaches involving loss of credit card data or email account information. In a few cases, the breaches involved loss of top secret and highly confidential data of national security value.

Here, ranked in ascending order of severity, are seven of the most significant government data breaches of the past three years.

 

 

Jai Vijayan is a seasoned technology reporter with over 20 years of experience in IT trade journalism. He was most recently a Senior Editor at Computerworld, where he covered information security and data privacy issues for the publication. Over the course of his 20-year ... View Full Bio

Previous
1 of 8
Next
Comment  | 
Print  | 
More Insights
Comments
Threaded  |  Newest First  |  Oldest First
kbannan100
50%
50%
kbannan100,
User Rank: Moderator
11/17/2016 | 10:59:38 PM
It's going to take a village
These breaches are just the tip of the iceberg. We all know that. One of the biggest problems is the amount of unsecured endpoints that are out there. Things like printers that aren't secured and laptops that aren't running antivirus or -- if they are -- have not been patched. It's going to take a lot more work on everyone's behalf before the good guys get ahead of the criminals. 

--Karen Bannan for IDG and HP
ONI SEO
50%
50%
ONI SEO,
User Rank: Apprentice
11/18/2016 | 11:34:05 AM
Mr ROBOT comes soon?
A great post with good questions/ But how to avoid that? What kind of solutions?
ClaireEllison
50%
50%
ClaireEllison,
User Rank: Apprentice
11/21/2016 | 4:22:24 PM
Re: amazing
A great post with good questions/ But how to avoid that? I really wanted to send a small word to say thanks to you for the fantastic points you are writing on this site.
COVID-19: Latest Security News & Commentary
Dark Reading Staff 7/9/2020
Russian Cyber Gang 'Cosmic Lynx' Focuses on Email Fraud
Kelly Sheridan, Staff Editor, Dark Reading,  7/7/2020
Why Cybersecurity's Silence Matters to Black Lives
Tiffany Ricks, CEO, HacWare,  7/8/2020
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
Special Report: Computing's New Normal, a Dark Reading Perspective
This special report examines how IT security organizations have adapted to the "new normal" of computing and what the long-term effects will be. Read it and get a unique set of perspectives on issues ranging from new threats & vulnerabilities as a result of remote working to how enterprise security strategy will be affected long term.
Flash Poll
The Threat from the Internetand What Your Organization Can Do About It
The Threat from the Internetand What Your Organization Can Do About It
This report describes some of the latest attacks and threats emanating from the Internet, as well as advice and tips on how your organization can mitigate those threats before they affect your business. Download it today!
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2020-15105
PUBLISHED: 2020-07-10
Django Two-Factor Authentication before 1.12, stores the user's password in clear text in the user session (base64-encoded). The password is stored in the session when the user submits their username and password, and is removed once they complete authentication by entering a two-factor authenticati...
CVE-2020-11061
PUBLISHED: 2020-07-10
In Bareos Director less than or equal to 16.2.10, 17.2.9, 18.2.8, and 19.2.7, a heap overflow allows a malicious client to corrupt the director's memory via oversized digest strings sent during initialization of a verify job. Disabling verify jobs mitigates the problem. This issue is also patched in...
CVE-2020-4042
PUBLISHED: 2020-07-10
Bareos before version 19.2.8 and earlier allows a malicious client to communicate with the director without knowledge of the shared secret if the director allows client initiated connection and connects to the client itself. The malicious client can replay the Bareos director's cram-md5 challenge to...
CVE-2020-11081
PUBLISHED: 2020-07-10
osquery before version 4.4.0 enables a priviledge escalation vulnerability. If a Window system is configured with a PATH that contains a user-writable directory then a local user may write a zlib1.dll DLL, which osquery will attempt to load. Since osquery runs with elevated privileges this enables l...
CVE-2020-6114
PUBLISHED: 2020-07-10
An exploitable SQL injection vulnerability exists in the Admin Reports functionality of Glacies IceHRM v26.6.0.OS (Commit bb274de1751ffb9d09482fd2538f9950a94c510a) . A specially crafted HTTP request can cause SQL injection. An attacker can make an authenticated HTTP request to trigger this vulnerabi...